This article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc.
> Any additional measures should not require ICANN to assume the role of a global content regulator or criminal-law authority.
> The community should instead consider whether contractual and operational arrangements adequately enable registries and registrars...
Those are things that are easy to say and hard to do. From the perspective of a good faith registrant, the enforcement is already too complex. There are hundreds of registries and thousands of registrars, all enforcing their own interpretation of the rules, so you end up with massive inconsistency.
No one wants their 10+ year old domain revoked for DNS abuse if they've been the victim of a security incident and it got misused, but dealing with that is hard and the economic structure of the industry isn't conducive to "intelligent" handling of complaints. Any solutions will scale the same as big tech with massive, automated systems that turn good faith participants into collateral damage.
A big problem for the domain industry is the way registries are shielded from liability and registrants. The registrars operate on thin margins and take on all the liability and customer support.
I don't think the registries will be given more responsibility. That's based on a personal bias though. I think the industry is set up to benefit the registries at the expense of registrars and registrants.
The registrars are the most likely party to be saddled with extra responsibility and I don't think that's a good solution because they have an economic incentive to look the other way. It's also a weakest link industry so, even if Porkbun, etc. are working overtime to keep bad actors off their platform, there's always someone willing to onboard a scammer for a few dollars.
In my opinion, there should be more talk about a centralized system funded by fees that ICANN collects. As a good faith registrant I want consistent, well defined rules with an appeals process, transparency etc.. I also don't care if I have to pay an extra dollar or two a year for my domains if it improves the industry overall.
Semi-related, does anyone know if there are any lists or decent sources for finding domains that have previously been suspended or put on block lists? That would be useful info for would-be registrants. No one wants to get surprised with a tainted domain.
I have some experience of dealing with this when working for .gov.uk
A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.
By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.
At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?
I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.
On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?
England have just scored the winning goal in the world cup and I want to celebrate by launching my personal tribute on Lionesses.rock
Why shouldn't that go live instantly?
A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.
I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because no one works weekends, I have to wait until next week before the domain is agreed.
I agree that there's no great harm in having to wait a day, or a week, for registration to complete. But in a world of instant gratification, it feels old fashioned.
None of these require a domain to work. There’s plenty precedent of things taking off without having a domain, eg Wordle, all Neal.fun sites, Hacker News, and I’m probably forgetting a few obvious ones.
I know that “mystupidvibecodedidea.com” is all the rage but nobody cares if that’s instead on yourname.com/mystupidvibecoded idea except you.
>A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.
More likely:
Some flavor of shit has hit the fan. I need to register some viable short and to the point domain names to get the word out faster than BigCo or the government and their army of lawyers can buy those domains.
Would we have stuff like DeFlock if there was an objection period?
What about if some advocacy firm was trying to create a website for people harmed by a drug. The drug company would just object to all their attempted registrations and bog them down.
A delay doesn’t even really hurt this use case. The first person to register the domain would still get it, 24 hours later, unless there’s an actual objection.
I think the "actual objection" is the hardest part.
The UK Government might legitimately object to the registration of `dwpgov-uk-payments.pizza` but should they be allowed to object to `dwp-gov-uk-stole-my-payments.fart`?
One might be obviously dodgy, the other is someone ranting about their experience. Do you think Governments should be able to object to domains complaining about them?
I agree with the premise but this article doesn't really provide a strong argument. It mentions stats about child exploitation but doesn't show how that's related to gtlds.
Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?
If you are thinking of launching your own TLD, or second level tld, or effective TLD (like vercel.app). I suggest being creative instead of making yet another TLD with the standard checkbox rules.
If your TLD is location based for example, consider verifying and linking the TLD to an identity, by local means, like a national ID.
This article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc.
https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...
> Any additional measures should not require ICANN to assume the role of a global content regulator or criminal-law authority.
> The community should instead consider whether contractual and operational arrangements adequately enable registries and registrars...
Those are things that are easy to say and hard to do. From the perspective of a good faith registrant, the enforcement is already too complex. There are hundreds of registries and thousands of registrars, all enforcing their own interpretation of the rules, so you end up with massive inconsistency.
No one wants their 10+ year old domain revoked for DNS abuse if they've been the victim of a security incident and it got misused, but dealing with that is hard and the economic structure of the industry isn't conducive to "intelligent" handling of complaints. Any solutions will scale the same as big tech with massive, automated systems that turn good faith participants into collateral damage.
A big problem for the domain industry is the way registries are shielded from liability and registrants. The registrars operate on thin margins and take on all the liability and customer support.
I don't think the registries will be given more responsibility. That's based on a personal bias though. I think the industry is set up to benefit the registries at the expense of registrars and registrants.
The registrars are the most likely party to be saddled with extra responsibility and I don't think that's a good solution because they have an economic incentive to look the other way. It's also a weakest link industry so, even if Porkbun, etc. are working overtime to keep bad actors off their platform, there's always someone willing to onboard a scammer for a few dollars.
In my opinion, there should be more talk about a centralized system funded by fees that ICANN collects. As a good faith registrant I want consistent, well defined rules with an appeals process, transparency etc.. I also don't care if I have to pay an extra dollar or two a year for my domains if it improves the industry overall.
Semi-related, does anyone know if there are any lists or decent sources for finding domains that have previously been suspended or put on block lists? That would be useful info for would-be registrants. No one wants to get surprised with a tainted domain.
I have some experience of dealing with this when working for .gov.uk
A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.
By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.
At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?
I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.
On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?
England have just scored the winning goal in the world cup and I want to celebrate by launching my personal tribute on Lionesses.rock
Why shouldn't that go live instantly?
A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.
I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because no one works weekends, I have to wait until next week before the domain is agreed.
I agree that there's no great harm in having to wait a day, or a week, for registration to complete. But in a world of instant gratification, it feels old fashioned.
None of these require a domain to work. There’s plenty precedent of things taking off without having a domain, eg Wordle, all Neal.fun sites, Hacker News, and I’m probably forgetting a few obvious ones.
I know that “mystupidvibecodedidea.com” is all the rage but nobody cares if that’s instead on yourname.com/mystupidvibecoded idea except you.
>A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.
More likely:
Some flavor of shit has hit the fan. I need to register some viable short and to the point domain names to get the word out faster than BigCo or the government and their army of lawyers can buy those domains.
Would we have stuff like DeFlock if there was an objection period?
What about if some advocacy firm was trying to create a website for people harmed by a drug. The drug company would just object to all their attempted registrations and bog them down.
A delay doesn’t even really hurt this use case. The first person to register the domain would still get it, 24 hours later, unless there’s an actual objection.
I think the "actual objection" is the hardest part.
The UK Government might legitimately object to the registration of `dwpgov-uk-payments.pizza` but should they be allowed to object to `dwp-gov-uk-stole-my-payments.fart`?
One might be obviously dodgy, the other is someone ranting about their experience. Do you think Governments should be able to object to domains complaining about them?
Who defines "actual objection"? The entrenched interests are really good at tilting such processes in their favor.
I agree with the premise but this article doesn't really provide a strong argument. It mentions stats about child exploitation but doesn't show how that's related to gtlds.
Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?
The internet DNS system is broken in multiple ways. We would do better to have a shared DHT table with unique keys addressable to names.
If you are thinking of launching your own TLD, or second level tld, or effective TLD (like vercel.app). I suggest being creative instead of making yet another TLD with the standard checkbox rules.
If your TLD is location based for example, consider verifying and linking the TLD to an identity, by local means, like a national ID.